Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

CISA CIRCIA Cyber-Incident Reporting Rule: 316,000-Entity Estimate and 2026 Status

CISA has not made CIRCIA incident or ransom-payment reports mandatory. Here is the 2026 rulemaking status, what the 316,000-company estimate represents, the NPRM's proposed deadlines and the records organizations should prepare.
From TheFinanceBase Team5 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No CIRCIA report is mandatory yet. CISA states: “Until the effective date of the final rule, organizations are not required to submit covered cyber incident or ransom payment reports under CIRCIA.” The proposed rule is still being developed as of September 28, 2026; a timetable entry in the 2026 Unified Agenda is not proof that a final, effective regulation has been published.

Where CIRCIA stands in 2026

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) directs the Cybersecurity and Infrastructure Security Agency (CISA) to establish reporting requirements for covered cyber incidents and ransom payments.

Proposed rule and comment period

CISA published its notice of proposed rulemaking (NPRM) on April 4, 2024. The comment period ultimately closed on July 3, 2024. The NPRM is not the final compliance rule, and its definitions, deadlines and reporting fields can change.

What CISA has done since the NPRM

CISA held four town halls in June 2026 and says it continues work on the final rule after funding lapses. The 2026 Unified Agenda lists the rule at the final-rule stage under RIN 1670-AA04 and includes a September 2026 timetable entry. That date is an internal planning milestone, not evidence that the final rule has been issued or taken effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does CIRCIA apply to your company?

A company cannot determine its final CIRCIA status from the NPRM alone. The final rule will establish which organizations qualify as covered entities and how the reporting thresholds apply. CISA’s estimate of the rule’s reach is therefore a proposal-stage estimate rather than a definitive list of regulated businesses.

What the proposal calls a covered cyber incident

The NPRM generally frames a covered cyber incident as a substantial cyber incident. Proposed triggers include one or more of the following:

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling
  • A substantial loss of confidentiality, integrity or availability of information or systems.
  • A serious impact on safety or the resiliency of operations.
  • Disruption of business or industrial operations, or of the delivery of goods and services.
  • Unauthorized access facilitated through a cloud-service provider, managed-service provider or third-party host.
  • A supply-chain compromise that produces the required level of impact.

These are proposed standards. The final definitions and any thresholds for particular sectors or entity types may differ.

What the 316,000 figure means

A 2024 U.S. House hearing record quotes a CISA estimate of more than 316,000 companies potentially affected by the proposed rule. The same record says CISA anticipated more than 15,000 incident reports per year. Both numbers are planning estimates tied to the proposal; they are not a final count of covered entities or a guaranteed annual workload.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Proposed reporting deadlines

The NPRM sets two principal clocks. Their starting points and treatment of follow-up information are summarized below.

Report Proposed trigger Proposed deadline Important qualification
Covered cyber-incident report When a covered entity reasonably believes a covered cyber incident occurred Within 72 hours The definition of a covered incident and the final clock could change.
Ransom-payment report Payment of ransom in connection with an incident Within 24 hours after payment This is a proposed obligation, not an operative CIRCIA deadline before the final rule takes effect.
Supplemental information Material developments after the initial submission As needed until the incident is concluded, fully mitigated and resolved The NPRM contemplates continuing updates rather than a single immutable filing.

One submission can cover both events

If a ransom payment occurs before the proposed incident-report deadline, the NPRM would allow one joint report to satisfy both proposed reporting obligations. Organizations would still need to provide later supplemental information until the matter is concluded and resolved.

How ransomware payments would be treated

The proposed 24-hour payment report is separate from the proposed 72-hour incident report unless the timing permits a joint submission. A payment report would capture payment and threat-actor details along with the incident information required by the rule. Because the NPRM is not final, organizations should not treat the proposed 24-hour period as a current CISA filing requirement.

What organizations should prepare now

CISA’s proposed data fields provide a practical basis for improving incident-response records, even though they are not a final compliance checklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Map existing records to likely CIRCIA fields

  • Affected systems, networks and devices.
  • Incident start, detection and mitigation dates.
  • Operational effects, including disruption to business, industrial activity or service delivery.
  • Details about unauthorized access and information affected.
  • Exploited vulnerabilities and defensive measures taken.
  • Attacker tactics, techniques and procedures.
  • Categories of information accessed or acquired.
  • Ransom-payment amount, method, timing and threat-actor information when applicable.

Preserve evidence for later updates

Incident logs, forensic images, identity and access records, cloud-provider notifications, communications with managed-service providers and payment documentation can help support an initial report and subsequent updates. Keep timestamps and decision records showing when the organization first reasonably believed an incident met the proposed threshold.

Assign ownership and escalation paths

Define who can declare an incident, who approves external reporting, how legal and security teams coordinate, and how executives are notified. Include cloud, managed-service, hosting and supply-chain contacts so that third-party evidence is available quickly.

Account for overlapping duties

CIRCIA would not automatically replace reporting required by the Securities and Exchange Commission, the Transportation Security Administration, a sector regulator, a state authority or a contract. Compare each obligation’s trigger threshold, clock start, ransom-payment treatment, data fields, supplemental-update rules, receiving agency, confidentiality or safe-harbor provisions, and any exception for a substantially similar report. The NPRM discusses such an exception, but the final rule may revise it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Voluntary reporting before the final rule

Although mandatory CIRCIA submissions are not yet in force, CISA encourages organizations to voluntarily report unusual cyber activity and incidents during the rulemaking period. CISA says this information helps it “rapidly deploy resources and render assistance to victims suffering attacks, analyze incoming reporting across sectors to spot trends, and quickly share that information with network defenders to warn other potential victims.” Organizations should use CISA’s current voluntary-reporting channels and confirm any submission instructions directly with the agency.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Preparation checklist for the final rule

  1. Identify the systems, services and business processes whose disruption would have significant operational or safety effects.
  2. Make sure incident-response records capture the proposed CIRCIA data fields and reliable timestamps.
  3. Document escalation criteria for suspected substantial incidents and ransom payments.
  4. Confirm contracts require timely notice from cloud, managed-service, hosting and other critical providers.
  5. Inventory other federal, state, sectoral and contractual reporting deadlines that could run at the same time.
  6. Set a process for preserving evidence and issuing supplemental updates as facts change.
  7. Monitor CISA’s final-rule publication and effective date rather than relying on the Unified Agenda’s planning date.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.